LIVE · cybersecurity feed
Live wire
breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform

zeroday.news ·

The Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) has confirmed that approximately 200 accounts were compromised in a cybersecurity incident affecting its Microsoft SharePoint servers. The breach, which was detected on July 28, involved the theft of login credentials for both user and technical accounts.

BIT's security specialists identified unusual activity on their SharePoint servers and, upon confirming an intrusion, promptly restricted internet access to the platform and addressed the exploited vulnerabilities. By July 31, it was determined that login credentials had been compromised, leading to an immediate password reset for all affected accounts.

The agency suspects the attackers leveraged vulnerabilities in Microsoft SharePoint that were publicly disclosed and patched in Microsoft's mid-July Patch Tuesday updates. While BIT has not specified which particular flaw was exploited, security analysts suggest the incident may have involved CVE-2026-56164, a SharePoint privilege escalation vulnerability, or CVE-2026-50522, a remote code execution flaw. The latter has been known to facilitate the theft of SharePoint machine keys, allowing attackers to maintain access even after servers are patched.

BIT is collaborating with the Federal Office for Cybersecurity (BACS) and Microsoft to investigate the incident. The agency stated that the affected SharePoint platform is not authorized to store confidential or highly sensitive personal data. As of now, there is no evidence indicating that data beyond the compromised login credentials was exfiltrated.

The attackers are described as previously unknown actors. No group has publicly claimed responsibility for the breach.

In compliance with Switzerland's Information Security Act, BIT reported the incident to BACS and the State Secretariat for Security Policy. Technical indicators related to the attack have also been shared with operators of essential infrastructure via the BACS platform.

Federal administration employees are able to continue accessing and sharing documents through alternative methods, according to BIT.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

security

Friday Squid Blogging: Arctic Bobtail Squid Video

Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.